linktree-sdk-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied partner documentation and external content from Linktree-related URLs to design adapters and implementation tests.
- Ingestion points: The skill reads user-provided documentation files and fetches external content via
WebFetch(e.g., fromlinktr.ee). - Boundary markers: The instructions emphasize creating a "vendor-neutral internal port" and using "redacted fixtures" to isolate external data from implementation code.
- Capability inventory: The skill possesses the capability to modify the repository using the
WriteandEdittools based on the analyzed data. - Sanitization: The instructions explicitly mandate the use of "sanitized fixtures" and advise the operator to never request or process credential values, cookies, or session material.
Audit Metadata